Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-38699 — TastyIgniter 3.0.7 allows XSS via the name field during user-account creation | Kitploit
Tools/GitHubGitHub/justin-1993/cve-2021-38699
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubjustin-1993/cve-2021-38699

CVE-2021-38699

TastyIgniter 3.0.7 allows XSS via the name field during user-account creation

View Repository
45 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-38699 TastyIgniter 3.0.7 allows XSS via the name field during user-account creation.

A Stored Cross Site Scripting Vulnerability exists in multiple pages of TastyIgniter v3.0.7 that allows for arbitrary execution of JavaScript. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38699

Vulnerable Pages: /account, /reservation, /admin/dashboard, /admin/system_logs

Vulnerable Payloads: “>

Found by Justin White and Matt Kiely | HuskyHacks, August 2021

Download Tool